Developing the Cloud ERP Cybersecurity Assessment Framework (CECAF) for Evidence-Based Cybersecurity Capability Assessment in Cloud ERP Platforms
Keywords:
Cloud ERP, Cybersecurity, Cybersecurity assessment framework, Cybersecurity capability assessment, Evidence-based assessment, Capability maturityAbstract
The purpose of this study is to develop the Cloud ERP Cybersecurity Assessment Framework (CECAF) to systematically evaluate cybersecurity capabilities in cloud ERP platforms. The framework was developed through the synthesis of academic literature, internationally recognised cybersecurity standards, cybersecurity capability maturity assessment principles, and cloud ERP-specific cybersecurity requirements, and demonstrated through an evidence-based assessment of Infor CloudSuite using publicly available official technical documentation. The findings demonstrate that CECAF enables a structured, transparent, and reproducible evaluation of cybersecurity capabilities across multiple assessment domains. The study contributes by introducing an analytical assessment framework tailored to cloud ERP platforms and by highlighting the methodological importance of documented technical evidence for objective cybersecurity capability assessment. The framework provides practical guidance for cybersecurity evaluation and comparative assessment of cloud ERP platforms.
Downloads
References
Almorsy, M., Grundy, J., & Müller, I. (2016). An analysis of the cloud computing security problem. Journal of Cloud Computing, 5(1), 38. https://doi.org/10.1186/s13677-016-0066-2
Anica-Popa, L.-E., Vrîncianu, M., Pugna, I.-B., & Boldeanu, D.-M. (2024). Addressing cybersecurity issues in ERP systems: Emerging trends and challenges. Proceedings of the International Conference on Business Excellence, 18(1), 1306–1323. https://doi.org/10.2478/picbe-2024-0108
Becker, J., Knackstedt, R., & Pöppelbuß, J. (2009). Developing maturity models for IT management: A procedure model and its application. Business & Information Systems Engineering, 1(3), 213–222. https://doi.org/10.1007/s12599-009-0044-5
Bertino, E. (2021). Zero Trust Architecture: Does It Help? IEEE Security & Privacy, 19(6), 95–99. https://doi.org/10.1109/MSEC.2021.3091195
Brezavšček, A., & Baggia, A. (2025). Recent trends in information and cyber security maturity assessment: A systematic literature review. Systems, 13(1), 52. https://doi.org/10.3390/systems13010052
Cloud Security Alliance. (2024). Cloud Controls Matrix (CCM). Retrieved from https://cloudsecurityalliance.org/research/cloud-controls-matrix
Demi, S., & Haddara, M. (2018). Do cloud ERP systems retire? An ERP lifecycle perspective. Procedia Computer Science, 138, 587–594. https://doi.org/10.1016/j.procs.2018.10.079
Dwivedi, Y. K., Hughes, L., Coombs, C., et al. (2021). Artificial Intelligence (AI): Multidisciplinary perspectives on emerging challenges, opportunities, and agenda for research, practice and policy. International Journal of Information Management, 57, 101994. https://doi.org/10.1016/j.ijinfomgt.2019.08.002
Infor. (2020). Infor Business Continuity Plan Overview. Retrieved from https://webassets.infor.com/images/Infor-Business-Continuity-Plan-Overview-April-2020.pdf
Infor. (2023). Information Security Plan (Software as a Service). Retrieved from https://dam.infor.com/api/public/content/94cc4621111741dfb603ed08dbb0f254
Infor. (2024). Data Privacy. Retrieved from https://www.infor.com/about/data-privacy
Infor. (n.d.). Audit Logging Documentation. Retrieved June 10, 2026, from https://docs.infor.com/
Infor. (n.d.). Federated Security. Retrieved June 9, 2026, from https://docs.infor.com/inforos/
Infor. (n.d.). Infor ION API Administration Guide. Retrieved June 10, 2026, from https://docs.infor.com/ionapi/
Infor. (n.d.). Infor OS API Gateway Administration Guide. Retrieved June 8, 2026, from https://docs.infor.com/inforos/
Infor. (n.d.). Infor OS Security Administration Guide. Retrieved June 10, 2026, from https://docs.infor.com/inforos/
Infor. (n.d.). Infor OS User Administration Guide. Retrieved June 9, 2026, from https://docs.infor.com/inforos/
Infor. (n.d.). Infor Trust Center. Retrieved June 10, 2026, from https://trust.infor.com/
International Organization for Standardization. (2022). ISO/IEC 27001:2022 Information security, cybersecurity and privacy protection—Information security management systems—Requirements. https://www.iso.org/standard/27001.html
Ivanović, T., & Marić, M. (2021). Cloud ERP systems in digital transformation: Opportunities and challenges. Strategic Management, 26(4), 28–40. https://doi.org/10.5937/StraMan2104028I
Khan, M. Y., Ab-Rahim, R., & Yeng, S. (2025). A conceptual overview of Enterprise Resource Planning systems. International Journal of Academic Research in Business and Social Sciences, 15(5). https://doi.org/10.6007/IJARBSS/v15-i5/25490
Khokrale, R. (2025). Cybersecurity in ERP-integrated supply chains: Risks and mitigation strategies. The Eastasouth Journal of Information System and Computer Science, 3(2). https://doi.org/10.58812/esiscs.v3i02.869
Klaus, H., Rosemann, M., & Gable, G. G. (2000). What is ERP? Information Systems Frontiers, 2(2), 141–162. https://doi.org/10.1023/A:1026543906354
Lee, Y., Lee, J., & Kim, S. (2024). Cybersecurity challenges and strategies in cloud ERP environments: A systematic literature review. Journal of Enterprise Information Management, 37(3), 742–768. https://doi.org/10.1108/JEIM-07-2023-0283
Liyanage, L., Arachchilage, N. A. G., & Russello, G. (2024). SoK: Identifying limitations and bridging gaps of cybersecurity capability maturity models (CCMMs). arXiv. https://doi.org/10.48550/arXiv.2408.16140
Llivisaca-Villazhañay, J., Paredes-Gualtor, J., Paredes-Valverde, M. A., & Ortiz-Crespo, A. (2025). Cloud ERP adoption and digital transformation in organisations: A systematic literature review. Information Systems Frontiers. Advance online publication. https://doi.org/10.1007/s10796-025-10625-5
Mushtaq, S., Mohsin, M., & Mushtaq, M. M. (2025). A systematic literature review on the implementation and challenges of Zero Trust Architecture across domains. Sensors, 25(19), 6118. https://doi.org/10.3390/s25196118
National Institute of Standards and Technology. (2024). The NIST Cybersecurity Framework (CSF) 2.0. U.S. Department of Commerce. https://www.nist.gov/cyberframework
Paulk, M. C., Curtis, B., Chrissis, M. B., & Weber, C. V. (1993). Capability Maturity Model, Version 1.1. IEEE Software, 10(4), 18–27. https://doi.org/10.1109/52.219617
Qazi, A., Khorram-Manesh, A., Vaziri, S., & Dimitrov, D. (2026). Cybersecurity capability assessment in cloud ERP systems: A maturity model approach. Computers & Security, 142, Article 103821. https://doi.org/10.1016/j.cose.2025.103821
Rose, S., Borchert, O., Mitchell, S., & Connelly, S. (2020). Zero trust architecture (NIST Special Publication 800-207). https://doi.org/10.6028/NIST.SP.800-207
Singh, U. K., & Sharma, A. (2021). Cloud computing security framework based on shared responsibility models: Cloud computing. In Cyber-Physical, IoT, and Autonomous Systems in Industry 4.0 (pp. 39-55). CRC Press.
Sternad Zabukovšek, S., & Bobek, S. (2025). Using the technology acceptance model for factors influencing acceptance of enterprise resource planning solutions. In Encyclopedia of Information Science and Technology, Sixth Edition (pp. 1-28). IGI Global Scientific Publishing.
Sunyaev, A. (2020). Internet computing: Principles of distributed systems and emerging internet-based technologies (2nd ed.). Springer. https://doi.org/10.1007/978-3-030-34957-8
Yin, R. K. (2018). Case study research and applications: Design and methods (6th ed.). SAGE Publications.
Downloads
Published
Data Availability Statement
Findings in this paper are based on publicly available technical documentation of Infor CSI (Infor, n.d.).
Issue
Section
License
Copyright (c) 2026 Staš Heric, Samo Bobek

This work is licensed under a Creative Commons Attribution-NonCommercial-NoDerivatives 4.0 International License.